Junglewise Threat Intelligence

CVE-1999-0202: GNU tar remote command execution in FTP sessions

CVE-1999-0202 · Severity: high · CVSS 7.5 · Published 1997-01-01

Technologies: Gnu Tar. Vendors: Gnu.

Executive brief

The GNU tar utility, a common tool for managing file archives, contains a vulnerability when used in conjunction with FTP sessions. An attacker could exploit this flaw to execute unauthorized commands on the system. This could lead to a complete system compromise, unauthorized data access, or service disruption.

Technical details

A command injection or remote code execution vulnerability exists in GNU tar when it is invoked during FTP sessions. The flaw likely stems from improper handling of filenames or archive metadata that are passed to the shell or system execution environment during automated FTP processing. A remote, unauthenticated attacker can exploit this by providing specially crafted inputs that trigger command execution. This allows for full system access with the privileges of the user running the tar process. While the specific root cause is categorized as 'Other' in historical records, the impact is a standard remote command execution (RCE) pattern.

Affected products

  • GNU tar

Timeline

  • 1997-01-01: disclosed: Vulnerability published in NVD.

References